Jump to content

PaulAllen

Honorary Members
  • Posts

    206
  • Joined

  • Last visited

Posts posted by PaulAllen

  1. Additional scan result of Farbar Recovery Scan Tool (x86) Version: 19-04-2015 01

    Ran by Earth at 2015-04-20 14:55:41

    Running from C:\Users\Earth\Desktop

    Boot Mode: Normal

    ==========================================================

     

     

    ==================== Security Center ========================

     

    (If an entry is included in the fixlist, it will be removed.)

     

    AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}

    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

    AS: Comodo Defense+ (Disabled - Up to date) {4BDD6856-AF0D-06BD-38AB-8A0FE39860CC}

    FW: COMODO Firewall (Enabled) {C8870897-C358-086B-2944-184866CC6D0A}

     

    ==================== Installed Programs ======================

     

    (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

     

    Arc (HKLM\...\{CED8E25B-122A-4E80-B612-7F99B93284B3}) (Version: 1.0.0.9668 - Perfect World Entertainment)

    Avast Free Antivirus (HKLM\...\Avast) (Version: 10.2.2215 - AVAST Software)

    CCleaner (HKLM\...\CCleaner) (Version: 5.03 - Piriform)

    COMODO Firewall (HKLM\...\{68BE8BAB-5375-4C99-9116-1808F5968D40}) (Version: 8.1.0.4426 - COMODO Security Solutions Inc.)

    EPSON Printer Software (HKLM\...\EPSON Printer and Utilities) (Version:  - )

    EPSON Scan (HKLM\...\EPSON Scanner) (Version:  - )

    GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)

    Google Chrome (HKLM\...\Google Chrome) (Version: 42.0.2311.90 - Google Inc.)

    Google Update Helper (Version: 1.3.21.169 - Google Inc.) Hidden

    Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden

    KeyScrambler (HKLM\...\KeyScrambler) (Version: 3.6.0.0 - QFX Software Corporation)

    Malwarebytes Anti-Malware version 2.1.4.1018 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation)

    Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)

    Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)

    Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)

    NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version:  - )

    SpywareBlaster 5.0 (HKLM\...\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC)

    WinPatrol (HKLM\...\{6A206A04-6BC1-411B-AA04-4E52EDEEADF2}) (Version: 33.1.2015.0 - WinPatrol)

     

    ==================== Custom CLSID (selected items): ==========================

     

    (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

     

     

    ==================== Restore Points  =========================

     

    15-04-2015 21:26:26 Scheduled Checkpoint

    18-04-2015 22:03:56 Scheduled Checkpoint

    19-04-2015 13:53:19 Scheduled Checkpoint

     

    ==================== Hosts content: ==========================

     

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

     

    2015-03-31 21:41 - 2015-04-19 12:28 - 00524227 ____A C:\Windows\system32\Drivers\etc\hosts

    127.0.0.1 localhost

    0.0.0.0 fr.a2dfp.net

    0.0.0.0 m.fr.a2dfp.net

    0.0.0.0 mfr.a2dfp.net

    0.0.0.0 ad.a8.net

    0.0.0.0 asy.a8ww.net

    0.0.0.0 static.a-ads.com

    0.0.0.0 atlas.aamedia.ro

    0.0.0.0 abcstats.com

    0.0.0.0 ad4.abradio.cz

    0.0.0.0 a.abv.bg

    0.0.0.0 adserver.abv.bg

    0.0.0.0 adv.abv.bg

    0.0.0.0 bimg.abv.bg

    0.0.0.0 ca.abv.bg

    0.0.0.0 www2.a-counter.kiev.ua

    0.0.0.0 track.acclaimnetwork.com

    0.0.0.0 accuserveadsystem.com

    0.0.0.0 www.accuserveadsystem.com

    0.0.0.0 achmedia.com

    0.0.0.0 csh.actiondesk.com

    0.0.0.0 ads.activepower.net

    0.0.0.0 app.activetrail.com

    0.0.0.0 stat.active24stats.nl #[Tracking.Cookie]

    0.0.0.0 traffic.acwebconnecting.com

    0.0.0.0 office.ad1.ru

    0.0.0.0 cms.ad2click.nl

    0.0.0.0 ad2games.com

    0.0.0.0 ads.ad2games.com

     

    There are 1000 more lines.

     

     

    ==================== Scheduled Tasks (whitelisted) =============

     

    (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

     

    Task: {28811A99-9E43-4C61-A166-751088E0548D} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-04-20] (COMODO)

    Task: {2E9BE86C-C8AC-49F3-B551-0C5FC694BEEF} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-03-22] (Piriform Ltd)

    Task: {744D7388-ACC0-4A2C-9534-C32AF11DA6B6} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\VistaSP1CEIP => C:\Windows\servicing\vsp1ceip.exe [2008-01-19] (Microsoft Corporation)

    Task: {98A92910-6200-4B2A-B90C-3F1BCB7F065E} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-03-23] (Avast Software s.r.o.)

    Task: {A3DDFCD4-F63D-42E3-AA78-77091AA7F8C3} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-04-20] (COMODO)

    Task: {BE69959B-50A7-494D-8FEC-36E98117D732} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2015-04-20] (COMODO)

    Task: {C2EF5941-0DCB-49CC-BE55-37875E076DDA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-03-22] (Google Inc.)

    Task: {EC11806B-13F2-47A6-A731-6A906F9251AD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-03-22] (Google Inc.)

     

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

     

    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe

    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

     

    ==================== Loaded Modules (whitelisted) ==============

     

    2015-03-22 15:27 - 2015-03-23 21:41 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll

    2015-03-22 15:27 - 2015-03-23 21:40 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll

    2015-04-19 12:01 - 2015-04-19 12:01 - 02926080 _____ () C:\Program Files\AVAST Software\Avast\defs\15041900\algo.dll

    2015-04-20 07:56 - 2015-04-20 07:56 - 02926080 _____ () C:\Program Files\AVAST Software\Avast\defs\15041901\algo.dll

    2015-03-22 15:27 - 2015-03-22 15:28 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll

     

    ==================== Alternate Data Streams (whitelisted) =========

     

    (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

     

    AlternateDataStreams: C:\Windows\avastSS.scr:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\adtschema.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Apphlpdm.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\appinfo.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\ARP.EXE:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\asycfilt.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\atl.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\atmfd.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\atmlib.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\AudioEng.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\AUDIOKSE.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\audiosrv.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\authui.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\avifil32.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\BthMtpContextHandler.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\cabview.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\cdd.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\certenc.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\certutil.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\clfs.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\clfsw32.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\comctl32.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\consent.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\crypt32.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\cryptdlg.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\cryptnet.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\cryptsvc.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\cscript.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\csrsrv.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d2d1.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3d10.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3d10core.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3d10level9.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3d10warp.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3d10_1.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3d10_1core.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\D3DCompiler_33.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\D3DCompiler_34.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\D3DCompiler_35.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\D3DCompiler_36.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\D3DCompiler_37.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\D3DCompiler_38.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\D3DCompiler_39.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\D3DCompiler_40.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\D3DCompiler_41.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\D3DCompiler_42.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dcsx_42.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx10.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx10_33.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx10_34.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx10_35.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx10_36.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx10_37.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx10_38.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx10_39.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx10_40.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx10_41.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx10_42.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx11_42.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx9_24.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx9_25.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx9_26.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx9_27.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx9_28.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx9_29.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx9_30.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx9_31.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx9_32.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx9_33.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx9_34.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx9_35.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\d3dx9_36.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\D3DX9_37.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\D3DX9_38.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\D3DX9_39.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\D3DX9_40.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\D3DX9_41.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\D3DX9_42.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\dciman32.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\dfshim.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\dnsapi.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\dnscacheugc.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\dnsrslvr.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\dpnet.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\dpnsvr.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\DWrite.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\dxmasf.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\dxtmsft.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\dxtrans.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\EncDec.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\EncDump.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\E_DCINST.DLL:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\E_FBCBADE.DLL:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\E_FBCHADE.DLL:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\E_FLMADE.DLL:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\fdco6.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\finger.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\FntCache.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\fontsub.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\FWPUCLNT.DLL:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\gameux.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\GameUXLegacyGDFs.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\gdi32.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\hccoin.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\hcrstco.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\HOSTNAME.EXE:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\httpapi.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\icaapi.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\icardagt.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\icardres.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\iccvid.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\idecoi.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\idecoiins.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\ieframe.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\iertutil.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\ieui.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\ieUnatt.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\IKEEXT.DLL:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\imagehlp.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\IMJP10K.DLL:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\inetcomm.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\inetcpl.cpl:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\infocardapi.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\iphlpsvc.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\iyuv_32.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\jscript.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\jscript9.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\jsproxy.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\kerberos.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\kernel32.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\L2SecHC.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\l3codeca.acm:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\l3codecp.acm:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\localspl.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\lpk.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\lsasrv.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\lsass.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\mciavi32.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\mciseq.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\mfc40.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\mfc40u.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\mfc42.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\mfc42u.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\MP4SDECD.DLL:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Mpeg2Data.ax:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\mpg2splt.ax:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\MpSigStub.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\MRINFO.EXE:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\mrt.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\msasn1.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\msaudite.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\MSCOMCTL.OCX:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\mscoree.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\mscorier.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\mscories.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\msctf.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\msdrm.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\MSDvbNP.ax:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\msdxm.ocx:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\msfeeds.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\msfeedsbs.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\msfeedssync.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\mshta.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\mshtml.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\mshtmled.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\msi.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\msihnd.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\msrle32.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\msshsq.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\MSSTDFMT.DLL:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\mstsc.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\mstscax.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\msv1_0.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\msvcrt.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\msvfw32.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\msvidc32.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\msxml3.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\msxml3r.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\msxml6.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\msyuv.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\ncrypt.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\ncsi.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\netapi32.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\netevent.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\netfxperf.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\netiohlp.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\NETSTAT.EXE:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\nlaapi.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\nlasvc.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\nshhttp.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\ntdll.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\ntkrnlpa.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\ntoskrnl.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\nvapi.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\nvcompiler.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\nvconrm.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\nvcuda.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\nvcuvenc.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\nvcuvid.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\nvd3dum.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\nvoglv32.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\nvuninst.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\nvunrm.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\nvwgf2um.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\odbc32.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\ole32.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\oleacc.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\oleaccrc.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\oleaut32.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\packager.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\PortableDeviceApi.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\PortableDeviceClassExtension.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\PortableDeviceConnectApi.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\PortableDeviceTypes.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\PortableDeviceWMDRM.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\PresentationHost.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\PresentationHostProxy.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\printcom.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\profsvc.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\psisdecd.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\psisrndr.ax:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\pwrshplugin.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\qdvd.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\qedit.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\quartz.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\rastls.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\rdpencom.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\RMActivate.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\RMActivate_isv.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\RMActivate_ssp.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\RMActivate_ssp_isv.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\ROUTE.EXE:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\rpcrt4.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\rtutils.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\sbe.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\sbeio.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\scesrv.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\schannel.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\schedsvc.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\scrrun.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\sdclt.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\secproc.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\secproc_isv.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\secproc_ssp.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\secproc_ssp_isv.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\secur32.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\shell32.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\shlwapi.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\shsvcs.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\smss.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\spoolsv.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\spwmp.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\srvsvc.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\synceng.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\SysFxUI.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\t2embed.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\taskcomp.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\taskeng.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\taskschd.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\TCPSVCS.EXE:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\termsrv.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\themeui.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\timedate.cpl:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\tsbyuv.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\TsWpfWrp.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\tzres.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\UIAnimation.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\UIAutomationCore.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\UIRibbon.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\UIRibbonRes.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\unregmp2.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\url.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\urlmon.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\usp10.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\vbscript.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Wdfres.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wdigest.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wecapi.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wecsvc.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wecutil.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wer.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wevtfwd.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\win32k.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\win32spl.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\WindowsCodecs.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\winhttp.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wininet.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\winmm.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\winrm.vbs:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\winrs.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\winrscmd.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\winrshost.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\winrsmgr.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\winrssrv.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\winsrv.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wintrust.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\winusb.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wkssvc.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wlanapi.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wlanmsm.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wlansec.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wlansvc.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\WMALFXGFXDSP.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wmi.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wmicmiplugin.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wmp.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wmpdxm.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\WMPhoto.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wmploc.DLL:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wmpmde.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\WMSPDMOD.DLL:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\WMVCORE.DLL:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\WMVDECOD.DLL:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wpdbusenum.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wpdshext.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\WPDShextAutoplay.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\WPDShServiceObj.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\WPDSp.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wpd_ci.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wscript.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\WSDApi.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wshcon.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wshom.ocx:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\WSManHTTPConfig.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\WSManMigrationPlugin.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\WsmAuto.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wsmplpxy.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wsmprovhost.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\WsmRes.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\WsmSvc.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\WsmWmiPl.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wuapi.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wuapp.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wuauclt.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wuaueng.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wucltux.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\WUDFCoinstaller.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\WUDFHost.exe:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\WUDFPlatform.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\WUDFSvc.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\WUDFx.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wudriver.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wups.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wups2.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\wuwebv.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\x3daudio1_0.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\x3daudio1_1.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\X3DAudio1_2.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\X3DAudio1_3.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\X3DAudio1_4.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\X3DAudio1_5.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\X3DAudio1_6.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\xactengine2_0.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\xactengine2_1.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\xactengine2_10.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\xactengine2_2.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\xactengine2_3.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\xactengine2_4.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\xactengine2_5.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\xactengine2_6.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\xactengine2_7.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\xactengine2_8.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\xactengine2_9.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\xactengine3_0.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\xactengine3_1.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\xactengine3_2.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\xactengine3_3.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\xactengine3_4.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\xactengine3_5.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\XAPOFX1_0.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\XAPOFX1_1.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\XAPOFX1_2.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\XAPOFX1_3.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\XAudio2_0.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\XAudio2_1.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\XAudio2_2.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\XAudio2_3.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\XAudio2_4.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\XAudio2_5.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\xinput1_1.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\xinput1_2.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\xinput1_3.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\xmllite.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\XpsGdiConverter.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\XpsPrint.dll:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\afd.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\ASACPI.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\bowser.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\dfsc.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\drmk.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\dxgkrnl.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\fastfat.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\fs_rec.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\http.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\ksecdd.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\mrxdav.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb10.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb20.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\ntfs.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\nvlddmkm.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\nvmfdx32.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\nvstor32.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\partmgr.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\portcls.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\rdpwd.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\Rtnicxp.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\srv.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\srv2.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\srvnet.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\tcpip.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\tcpipreg.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\tssecsrv.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\tunnel.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\usb8023.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\usbccgp.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\usbd.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\usbehci.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\usbhub.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\usbohci.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\usbport.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\usbprint.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\usbscan.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\volsnap.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\Wdf01000.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\WdfLdr.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\WUDFPf.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\WUDFRd.sys:$CmdTcID

    AlternateDataStreams: C:\Windows\system32\Drivers\etc\HOSTS:$CmdZnID

    AlternateDataStreams: C:\ProgramData\TEMP:5C321E34

    AlternateDataStreams: C:\Users\Earth\Desktop\FRST.exe:$CmdZnID

    AlternateDataStreams: C:\Users\Earth\Desktop\gillespetersonww-chaka-khan-words-and-music.mp3:$CmdZnID

    AlternateDataStreams: C:\Users\Earth\Documents\KeyScrambler_Setup.exe:$CmdTcID

    AlternateDataStreams: C:\Users\Earth\Documents\lightworks_v12.0.2_full_32bit_setup.exe:$CmdTcID

    AlternateDataStreams: C:\Users\Earth\Documents\mediabrowser_4_instruction_guide.pdf:$CmdZnID

    AlternateDataStreams: C:\Users\Earth\Documents\npp.6.7.3.Installer.exe:$CmdTcID

    AlternateDataStreams: C:\Users\Earth\Documents\privatetunnel-win-2.4.exe:$CmdTcID

     

    ==================== Safe Mode (whitelisted) ===================

     

    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

     

     

    ==================== EXE Association (whitelisted) ===============

     

    (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

     

     

    ==================== Other Areas ============================

     

    (Currently there is no automatic fix for this section.)

     

    HKU\S-1-5-21-2376867508-200169253-45356126-1000\Control Panel\Desktop\\Wallpaper -> 

    DNS Servers: 192.168.1.254

     

    ==================== MSCONFIG/TASK MANAGER disabled items ==

     

    (Currently there is no automatic fix for this section.)

     

    MSCONFIG\Services: ArcService => 3

    MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Device Monitor 4.lnk => C:\Windows\pss\Device Monitor 4.lnk.CommonStartup

    MSCONFIG\startupreg: EPSON Stylus DX4800 Series => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE /F "C:\Windows\TEMP\E_SB7ED.tmp" /EF "HKLM"

    MSCONFIG\startupreg: Windows Defender => %ProgramFiles%\Windows Defender\MSASCui.exe -hide

     

    ==================== Accounts: =============================

     

    Administrator (S-1-5-21-2376867508-200169253-45356126-500 - Administrator - Disabled)

    Earth (S-1-5-21-2376867508-200169253-45356126-1000 - Administrator - Enabled) => C:\Users\Earth

    Guest (S-1-5-21-2376867508-200169253-45356126-501 - Limited - Disabled)

     

    ==================== Faulty Device Manager Devices =============

     

     

    ==================== Event log errors: =========================

     

    Application errors:

    ==================

    Error: (04/14/2015 11:08:08 PM) (Source: Perflib) (EventID: 1008) (User: )

    Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4

     

    Error: (04/14/2015 10:07:10 AM) (Source: Perflib) (EventID: 1010) (User: )

    Description: EmdCacheC:\Windows\system32\emdmgmt.dll4

     

    Error: (04/10/2015 08:22:36 AM) (Source: Application Hang) (EventID: 1002) (User: )

    Description: The program GameClient.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.

    Process ID: 700

    Start Time: 01d0735ed3c55741

    Termination Time: 42

     

    Error: (04/10/2015 08:12:44 AM) (Source: Application Hang) (EventID: 1002) (User: )

    Description: The program GameClient.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.

    Process ID: 12e8

    Start Time: 01d0735d29028c21

    Termination Time: 45

     

    Error: (04/10/2015 08:07:49 AM) (Source: Application Hang) (EventID: 1002) (User: )

    Description: The program GameClient.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.

    Process ID: 11f8

    Start Time: 01d0735cbe5b3bb1

    Termination Time: 45

     

    Error: (04/05/2015 05:55:53 PM) (Source: Perflib) (EventID: 1010) (User: )

    Description: EmdCacheC:\Windows\system32\emdmgmt.dll4

     

    Error: (04/02/2015 01:47:15 PM) (Source: Perflib) (EventID: 1010) (User: )

    Description: EmdCacheC:\Windows\system32\emdmgmt.dll4

     

    Error: (03/31/2015 10:36:54 AM) (Source: Perflib) (EventID: 1010) (User: )

    Description: EmdCacheC:\Windows\system32\emdmgmt.dll4

     

    Error: (03/26/2015 06:15:27 PM) (Source: Application Error) (EventID: 1000) (User: )

    Description: Faulting application print.exe, version 2.8.14.0, time stamp 0x00000000, faulting module RPCRT4.dll, version 6.0.6002.18882, time stamp 0x51dd2d9c, exception code 0xc0000005, fault offset 0x0003b9e8,

    process id 0x6c4, application start time 0xprint.exe0.

     

    Error: (03/26/2015 01:26:17 PM) (Source: Application Error) (EventID: 1000) (User: )

    Description: Faulting application nvcplui.exe, version 7.8.760.0, time stamp 0x53b45eac, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code 0xc0000005, fault offset 0x00000000,

    process id 0x11a0, application start time 0xnvcplui.exe0.

     

     

    System errors:

    =============

    Error: (04/15/2015 08:37:58 PM) (Source: volsnap) (EventID: 14) (User: )

    Description: The shadow copies of volume C: were aborted because of an IO failure on volume C:.

     

    Error: (04/12/2015 11:20:20 PM) (Source: Service Control Manager) (EventID: 7031) (User: )

    Description: Windows Search1300001Restart the service

     

    Error: (04/12/2015 11:20:19 PM) (Source: Service Control Manager) (EventID: 7034) (User: )

    Description: MBAMService1

     

    Error: (04/12/2015 11:20:19 PM) (Source: Service Control Manager) (EventID: 7034) (User: )

    Description: MBAMScheduler1

     

    Error: (04/12/2015 11:20:19 PM) (Source: Service Control Manager) (EventID: 7031) (User: )

    Description: Print Spooler1600001Restart the service

     

    Error: (04/12/2015 11:20:19 PM) (Source: Service Control Manager) (EventID: 7031) (User: )

    Description: Software Licensing11200001Restart the service

     

    Error: (04/09/2015 08:22:13 PM) (Source: EventLog) (EventID: 6008) (User: )

    Description: The previous system shutdown at 20:20:41 on 09/04/2015 was unexpected.

     

    Error: (04/09/2015 08:20:11 PM) (Source: Service Control Manager) (EventID: 7000) (User: )

    Description: Volume Shadow Copy%%1053

     

    Error: (04/09/2015 08:20:11 PM) (Source: Service Control Manager) (EventID: 7009) (User: )

    Description: 30000Volume Shadow Copy

     

    Error: (04/09/2015 08:20:10 PM) (Source: DCOM) (EventID: 10005) (User: )

    Description: 1053VSS{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}

     

     

    Microsoft Office Sessions:

    =========================

    Error: (04/14/2015 11:08:08 PM) (Source: Perflib) (EventID: 1008) (User: )

    Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4

     

    Error: (04/14/2015 10:07:10 AM) (Source: Perflib) (EventID: 1010) (User: )

    Description: EmdCacheC:\Windows\system32\emdmgmt.dll4

     

    Error: (04/10/2015 08:22:36 AM) (Source: Application Hang) (EventID: 1002) (User: )

    Description: GameClient.exe0.0.0.070001d0735ed3c5574142

     

    Error: (04/10/2015 08:12:44 AM) (Source: Application Hang) (EventID: 1002) (User: )

    Description: GameClient.exe0.0.0.012e801d0735d29028c2145

     

    Error: (04/10/2015 08:07:49 AM) (Source: Application Hang) (EventID: 1002) (User: )

    Description: GameClient.exe0.0.0.011f801d0735cbe5b3bb145

     

    Error: (04/05/2015 05:55:53 PM) (Source: Perflib) (EventID: 1010) (User: )

    Description: EmdCacheC:\Windows\system32\emdmgmt.dll4

     

    Error: (04/02/2015 01:47:15 PM) (Source: Perflib) (EventID: 1010) (User: )

    Description: EmdCacheC:\Windows\system32\emdmgmt.dll4

     

    Error: (03/31/2015 10:36:54 AM) (Source: Perflib) (EventID: 1010) (User: )

    Description: EmdCacheC:\Windows\system32\emdmgmt.dll4

     

    Error: (03/26/2015 06:15:27 PM) (Source: Application Error) (EventID: 1000) (User: )

    Description: print.exe2.8.14.000000000RPCRT4.dll6.0.6002.1888251dd2d9cc00000050003b9e86c401d067e852d76771

     

    Error: (03/26/2015 01:26:17 PM) (Source: Application Error) (EventID: 1000) (User: )

    Description: nvcplui.exe7.8.760.053b45eacunknown0.0.0.000000000c00000050000000011a001d067bffece5430

     

     

    CodeIntegrity Errors:

    ===================================

      Date: 2015-04-20 14:55:21.971

      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

     

      Date: 2015-04-20 14:55:21.831

      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

     

      Date: 2015-04-20 14:55:21.675

      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

     

      Date: 2015-04-20 14:55:21.535

      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

     

      Date: 2015-04-20 07:54:44.266

      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

     

      Date: 2015-04-20 07:54:44.125

      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

     

      Date: 2015-04-20 07:54:43.985

      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

     

      Date: 2015-04-20 07:54:43.798

      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

     

      Date: 2015-04-20 07:54:43.626

      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

     

      Date: 2015-04-20 07:54:43.455

      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

     

     

    ==================== Memory info =========================== 

     

    Processor: Intel® Core2 Quad CPU Q6600 @ 2.40GHz

    Percentage of memory in use: 38%

    Total physical RAM: 3581.63 MB

    Available physical RAM: 2205.95 MB

    Total Pagefile: 7370.23 MB

    Available Pagefile: 5920.46 MB

    Total Virtual: 2047.88 MB

    Available Virtual: 1903.21 MB

     

    ==================== Drives ================================

     

    Drive c: () (Fixed) (Total:931.51 GB) (Free:881.33 GB) NTFS ==>[Drive with boot components (obtained from BCD)]

     

    ==================== MBR & Partition Table ==================

     

    ========================================================

    Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 931.5 GB) (Disk ID: 93D0ECF1)

    Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)

     

    ==================== End Of Log ============================

  2. I agree with what the others said that if no trust is in a relation ship it's not going anywhere good so I'd leave, this sort of relation ship rarely ends well.

    But if you really don't want to leave him then go out and buy a pay as you go dongle and use it for anything private, wipe all traces of your use from your machine after you have done anything private, encase he logs onto your machine to see what you have been doing which to me would be more likely what hes been doing. Oh and don't let him know you have the dongle.

    Of course I am assuming your not up to anything yourself and trying to use the sneakiness of people here to make sure you don't get caught :P no offence meant but I don't know you from Adam and I'm always suspicious of every one.

    Hope you get your situation resolved.

  3. Hi as from the title I keep getting gone8.com a browser hijacker trying to dial out and Mbam keeps blocking it.

    Whats wierd is I have gone into the registry to find it and it's not there and neither are any files I can see to remove.

    I ran hitman pro and adw cleaner and neither find it, I've also ran a full scan with mbam and avast.

    It shows no signs of ever infecting my browser what so ever and only time I know something is up is when I see mbam blocking it.

    I must be missing something and need some help with finding whats causing it.

    Thank you 

  4. Hi heres my problem the text in my browser has gone wierd it has lines pointing up, this is on both vista machines, and the net has slowed down considerably, the windows 7 machine the text is OK in chrome as it should be.

     

    Here is what I have tried so far each has failed to resolve the issue:

    Reset chrome browser to default.

    Uninstalled and then reinstalled Chrome.

    Scanned for malware with Malewarebytes, Trendmicro, MSE, Tddskiller, Avast, Rouge killer, Combo fix.

    Reinstalled 1 pc to a clean install.

     

    None of the above has worked the problem still exists, I reset the router to default as well just to be safe.

    If it is malware then its probably nasty as it can survive a clean install, Oh yeah I took the cmos battery out and RAM and left the machine for a good hour to make sure all memory was wiped

     

    I enclose a picture of the text you'll have to zoom in to see the little lines.

    the rouge killer picture shows some stuff it found I think that is related to avast, being it has asw in its title.

     

     

    I need help with this one please thank you very much for any kind assistance given

    Paul Allen

  5. Hello thanks for the reply.

    Ive been looking at all the ip's that tried to connect to me when downloading this game (the ones that triggered the network attacks on my firewall) it is in my personal opinion a tad weird that they come from Russia, France, Sweden and there was a few more counties too so I think I will leave this game as most games download from a single location they may have a few different ips but normally the same country same location this doesn't feel right to me, thanks for your time.

    Should I still post in the False pos section for you to look at or not?

     

    P Allen

  6. I started to download a legit game called warthunder and then Mbam went blocking it as you can see

     
    Detection, 16/11/2014 12:44:32, SYSTEM, NUTHATCH-PC, Protection, Malicious Website Protection, IP, 159.224.150.104, 49736, Outbound, C:\Program Files\WarThunder\launcher.exe, 
    Detection, 16/11/2014 12:46:08, SYSTEM, NUTHATCH-PC, Protection, Malicious Website Protection, IP, 217.23.187.92, 27032, Outbound, C:\Program Files\WarThunder\launcher.exe, 
     
    Also my firewall stopped 102 inbound network intrusions at the same time, my question is something wrong with warthunder or is this all just FP.
    I've checked for malware can't find a thing, scanned and looked with various tools all so checked outbound connections can't see any signs of malware.
    I stopped downloading warthunder and deleted it from my system to be safe.
     
    Here is another topic on warthunder from another user of mbam, no answers did I find in it
     
    Great full for your help and assistance
    P.Allen
  7. @Gonzo

    Thanks for the reply. Mistakes happen all is well so it doesn't matter, from time to time these things do happen.

     

    @Advancedsetup

    Thanks for the link. I had already sorted it doing what you described. I'm always cautious when something like this happens and a window comes up with do you want to bla bla in case its some malware, not that I look at nude women or download illegal content that might get me infected. really I don't look at nude women.

    I've said to much, I must make a swift retreat fair well and thanks mbam team

     

    P. Allen

  8. Hi I did an update and now malicious website protection is disabled and will not reactivate even when turned off and on again. I restarted the machine and still its off, I turned it on manually and its on on the tick boxes but mbam reports it to be still off. when i tried to do a scan it said it had become corrupt do I want to down load a new data base I said no for now as I wasn't sure if I am infected and it was malware, judging by some posts here it looks like it is your update that has caused this. what should i do now, as i am not getting the download sign again like in the other post where he/she says it fixed it for them. Download a new copy or wait till the update is corrected. I shall have a nice cup of tea while I wait?

    I await your reply like a bear about to catch a salmon

  9. Thanks gents for the reply :)

    This has been going on for over a year every day relentlessly is that still OK? and I have just discovered an infected userinit.exe file (found by combofix) on her main computer.

    I do play games on this computer but only Neverwinter and dont visit any bad sites and I know she does not do anything bad on it as in looking at dubious sites so where and how did this file infect it. Its got past scotty dog, avast, mbam pro, mbae, and comodo firewall and hips. (no bad emaisl have been opened by either of us)

    is it me or could something be up here?

    I never get anything on my own pc or have any attacks on my router apart from the odd port scan like you say certainly not the amount she gets on a daily basis if they keep rising she will be competing with NASA or some places in silicon valley lol.

    Thanks again gents

  10. Hello new to this site, I'm Paul hello. 

    Here's my problem well not mine my Grans, I look in her routers firewall log and see 100s of remote attempts a week to gain remote access mostly from china. what can I do about this.

    so far I have written to china telecom and showed them the logs and they just blanked me so I'm guessing they don't care or it's state sponsored so they can use it to hide behind to hack more sensitive targets.

    My computer level is stone-age so don't be to technical with any answers, I know how to turn it on and push the buttons uggg and how to play games.

    Thanks for your answers if any 

    Paul Allen (stone-age man)

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.